Vulnerabilities > MAX 3000

DATE CVE VULNERABILITY TITLE RISK
2022-02-28 CVE-2022-25410 Cross-site Scripting vulnerability in Max-3000 Maxsite CMS 108
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
network
low complexity
max-3000 CWE-79
5.4
2022-02-28 CVE-2022-25411 Unrestricted Upload of File with Dangerous Type vulnerability in Max-3000 Maxsite CMS 108
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
network
low complexity
max-3000 CWE-434
critical
9.8
2022-02-28 CVE-2022-25412 Path Traversal vulnerability in Max-3000 Maxsite CMS 108
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
network
low complexity
max-3000 CWE-22
8.1
2022-02-28 CVE-2022-25413 Cross-site Scripting vulnerability in Max-3000 Maxsite CMS 108
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
network
low complexity
max-3000 CWE-79
5.4
2021-12-10 CVE-2021-27983 Unspecified vulnerability in Max-3000 Maxsite CMS 107.5
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
network
low complexity
max-3000
critical
9.8